Daniel Winzen
Daniel Winzen
phpmyadmin, adminer and squirrelmail are publicly accessible, adding attack vectors. They should only be accessible by users logged in to their hosting account, possibly with one-click login from the dashboard.
using mail() the name is ignored and always overridden with a fixed address. It should be possible to leave the name and only override the sender address
#11 should be implemented first.
A spammer can abuse guest accounts to distribute questionable messages, without the staff being able to do anything about it, if they are unaware of the abusive guests. To keep...